CVE-2025-40804
Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
09/09/2025
Last modified:
09/09/2025
Description
A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions). The affected application exposes a network share without any authentication. This could allow an attacker to access or alter sensitive data without proper authorization.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
9.10
Severity 3.x
CRITICAL



